SB2026091104 - IBM WebSphere Application Server - Liberty update for Apache CXF
Published: September 11, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) XML External Entity injection (CVE-ID: CVE-2026-65432)
CWE-ID: CWE-611 - Improper Restriction of XML External Entity Reference ('XXE')
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to improper restriction of XML external entity references in WSDL4J import parsing when processing imported WSDL or XSD documents referenced by a top-level WSDL. A remote attacker can supply a specially crafted imported WSDL or XSD document to disclose sensitive information.
The issue affects imported documents referenced through <wsdl:import> or <xsd:import>, while the top-level WSDL is processed through a hardened parsing path.
Remediation
Install update from vendor's website.